Installation

Is there a workaround for avoiding the 30-day violation after exceeding permitted volume usage on Enterprise trial?

HQ5452
Explorer

Hi,

There are three days between the end of my trial and the moment I change my stack from "Splunk Enterprise" to "Splunk Free". During this three days, allowed permitted volume was 0GB, so I exceeded the "5 violations in a rolling 30 day window" permitted.

Is it possible to ignore (or something else) this three days of violation, and allow me to use my Splunk again without having to delay the 30 day window?

Thanks for your help,

JB

Labels (1)
0 Karma

SplunkersRock
Path Finder
0 Karma

HQ5452
Explorer

I didn't want to create an alert on license usage.
Anyway I installed a new instance but i lose indexed data.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...